What is CVE-2026-11707?
This critical vulnerability is a cross-site scripting (XSS) flaw found in the administrative console login page of IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server. An attacker could exploit this to inject malicious scripts into user sessions. It is strongly recommended to apply the security updates provided by IBM as soon as possible.
Azərbaycanca: Bu kritik boşluq IBM Tivoli System Automation Application Manager 4.1 və IBM WebSphere Application Server-in inzibati konsol giriş səhifəsində aşkarlanmış cross-site scripting (XSS) zəifliyidir. Təcavüzkar bu boşluqdan istifadə edərək istifadəçilərə zərərli skript yeridə bilər. Mümkün qədər tez IBM tərəfindən təqdim edilən təhlükəsizlik yeniləməsini tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: IBM
FAQ2
Which software are affected by CVE-2026-11707?
This XSS vulnerability was found in the administrative console login page of IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server.
What should I do to protect against CVE-2026-11707?
It is strongly recommended to apply the security updates provided by IBM as soon as possible.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.